A–Z
Glossary
Plain-language definitions of the USB forensics terms used across the guides.
- ContainerID
- A GUID Windows gives to all device nodes that belong to the same physical device, linking Enum\USB, Enum\USBSTOR and SWD\WPDBUSENUM entries.
- Device instance ID
- The path-like name Windows gives a device node, such as USBSTOR\Disk&Ven_X&Prod_Y&Rev_1.00\SERIAL&0, used across the registry, logs and setupapi.
- Device property timestamps (0064–0067)
- FILETIMEs under a device's Properties\{83da6326-…} key: 0064 install date, 0065 first install, 0066 last arrival, 0067 last removal.
- EMDMgmt
- A SOFTWARE hive key written by ReadyBoost that pairs a USB device's serial with its volume label and volume serial number.
- MountedDevices
- The SYSTEM hive key mapping drive letters and volume GUIDs to the disk or device each volume belongs to.
- MountPoints2
- The NTUSER.DAT key listing volumes mounted in a user's session, by volume GUID: the registry link between a USB device and an account.
- Partition/Diagnostic event 1006
- The Windows 10+ event logged on each disk arrival, with model, serial, capacity, partition table and volume boot records.
- USBSTOR
- The SYSTEM hive key Enum\USBSTOR, where Windows keeps one entry per USB mass-storage device with vendor, product, revision and serial.
- Volume GUID
- The identifier Windows assigns to each volume it mounts, as in \\?\Volume{…}; it links MountedDevices to each user's MountPoints2.
- Volume serial number (VSN)
- The 32-bit serial written into a volume's boot sector when it is formatted, shown as XXXX-XXXX and stored in shortcuts and Jump Lists.
- Windows-generated serial
- A USB instance ID made up by Windows when the device reports no usable serial, recognisable by an & in second position, as in 7&1f2e3d4c&0.
- WPDBUSENUM
- The Windows Portable Devices enumerator: SWD\WPDBUSENUM registry entries whose FriendlyName is a USB volume's label or drive letter.